Five engagements. One method behind all of them.
An assessment is scoped to the decision it has to support, so we name our engagements after the decision rather than after a product. The method underneath does not change, and neither does the scale we score on.
Recommended engagement
System or platform assessment
One application or environment, scored end to end against the decision in front of you.
See this engagement01
System or platform assessment
Trigger: One application, environment or vendor deployment that is already in use.
Choose this when a single system carries the decision. It is the tightest scope we run and the fastest to a defensible answer.
See this engagement02
Programme or estate assessment
Trigger: Several systems, shared services or an entire estate.
Choose this when you need to compare exposure across systems and decide where the next dollar goes. Risk is normalised on one scale so the comparison holds.
See this engagement03
Change or adoption assessment
Trigger: A new tool, supplier or architecture you have not committed to yet.
Choose this before signing. You get the residual risk and the conditions under which accepting it is reasonable, while you still have leverage.
See this engagement04
Threat modelling
Trigger: A system in design, or an architecture under review.
Choose this when you need the threat model itself rather than a scored register. It fits design reviews, and it feeds a full assessment later without rework.
See this engagement05
Reassessment
Trigger: A system or programme we have scored before.
Choose this after remediation, or on an annual cycle. Because the anchors do not move, the delta is real movement rather than a change of opinion.
See this engagementWhatever the shape, these do not change.
The engagement name describes the scope. It does not describe a different standard of work.
Likelihood and impact, 1 to 5
A score means the same thing across systems, across engagements and across years.
Inherent and residual
Every risk is scored before controls and again after them, so the value of your existing security is visible.
Findings someone holds
A risk with no owner is a risk nobody closes, so the register assigns one to each.
Reasoning you can audit
Each rating records what it was based on, so a challenge can be answered with evidence.
A penetration test proves a specific weakness can be exploited. An assessment establishes what is at risk, how likely the harm is and what it would cost you, then ranks it. The two answer different questions, and we will say so when a test would sharpen the picture rather than sell you an assessment that cannot.
We also say when the answer is that you do not need us yet. An organization without an asset inventory is better served by building one first, and we would rather tell you that than bill for a register built on guesses.
What an assessment is not.
Not sure which one fits?
Describe the decision you are facing and we will tell you which engagement answers it, including when the answer is a smaller one than you expected.